/var/log/secure 一般用来记录安全相关的信息,记录最多的是哪些用户登录服务器的相关日志,如果该文件很大,说明有人在破解你的 root 密码
[root@liesys ~]# tail /var/log/secure
Oct 24 09:13:34 redis1 sshd[14021]: Accepted password for root from 192.168.30.169 port 59260 ssh2
Oct 24 09:13:34 redis1 sshd[14021]: pam_unix(sshd:session): session opened for user root by (uid=0)
Oct 24 09:13:35 redis1 sshd[14031]: Accepted password for root from 192.168.30.169 port 59261 ssh2
Oct 24 09:13:35 redis1 sshd[14031]: pam_unix(sshd:session): session opened for user root by (uid=0)
可以分为几个字段来描述这些事件信息:
1. 事件的日期和时间
2. 事件的来源主机 ( 通常是写主机名 )
3. 产生这个事件的程序[进程号]
4. 实际的日志信息
常见信息:
# 表示root用户关闭了会话(也就是关闭了终端)
Jan 17 12:27:36 139 sshd[12812]: pam_unix(sshd:session): session closed for user root
# 表示接受来自14.23.168.10的root用户的公钥登录
Jan 17 12:28:59 139 sshd[14064]: Accepted publickey for root from 14.23.168.10 port 36637 ssh2
# 表示给root用户打开一个终端
Jan 17 12:28:59 139 sshd[14064]: pam_unix(sshd:session): session opened for user root by (uid=0)
# 表示已经连着的终端主动断开连接,并关闭终端
Jan 17 14:41:10 Mir2_Center sshd[9913]: Received disconnect from 183.60.122.237: 11: disconnected by user
Jan 17 14:41:10 Mir2_Center sshd[9913]: pam_unix(sshd:session): session closed for user root
# 表示对端使用无效的用户redis来连接
Jan 17 14:39:48 139 sshd[31261]: Invalid user redis from 45.115.45.3 port 33274
# 本机对redis用户进行认证,认证失败,发送错误信号给对端
Jan 17 14:39:48 139 sshd[31261]: input_userauth_request: invalid user redis [preauth]
# 对端接收到错误信号主动断开连接
Jan 17 14:39:48 139 sshd[31261]: Received disconnect from 45.115.45.3 port 33274:11: Bye Bye [preauth]
# 连接关闭
Jan 17 14:39:48 139 sshd[31261]: Disconnected from 45.115.45.3 port 33274 [preauth]